Back to search
CVE-2007-0667
Published: Feb 2, 2007
Modified: Aug 7, 2024
PUBLISHED
Description
The redirect function in Form.pm for (1) LedgerSMB before 1.1.5 and (2) SQL-Ledger allows remote authenticated users to execute arbitrary code via redirects, related to callbacks, a different issue than CVE-2006-5872.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
20070127 Arbitrary Code Execution in SQL-Ledger and LedgerSMB through redirects
mailing-list
x_refsource_BUGTRAQ
20070206 Unofficial SQL-Ledger patch for CVE-2007-0667
mailing-list
x_refsource_BUGTRAQ
2217
third-party-advisory
x_refsource_SREASON
ADV-2007-0407
vdb-entry
x_refsource_VUPEN
22295
vdb-entry
x_refsource_BID
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now